What is CMMC and do you need it? (subcontractor flow-down explained)

A plain-English guide to what CMMC is, the three certification levels, and how subcontractor flow-down can pull your small business into the requirement.

What is CMMC and do you need it? (subcontractor flow-down explained)

CMMC tends to land on a small business the way a cold front rolls in: suddenly, and from someone above you in the supply chain. A prime contractor sends a notice, or a new contract clause appears, and now there’s an acronym you’re expected to satisfy by a date you didn’t pick. Two questions actually matter here: what CMMC is, and whether it reaches you.

What CMMC is

CMMC stands for Cybersecurity Maturity Model Certification. It is the U.S. Department of Defense’s program for verifying that companies in the defense supply chain are actually protecting sensitive government information, rather than just claiming to. The official details live on the DoD’s CMMC program page.

The reason it exists is straightforward. For years, defense contractors were required by contract to protect certain information but were largely trusted to self-attest that they did. Too often the controls were not really in place. CMMC adds verification, ranging from a self-assessment to a third-party audit depending on how sensitive the information is.

There are two categories of information the rules care about. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not meant for public release. Controlled Unclassified Information (CUI) is more sensitive: technical specs, drawings, and similar material that requires protection by law or policy. Which one you touch largely determines which level applies to you.

The three levels

The program is built on three levels, and the official CMMC model overview lays them out:

Level 1 (Foundational). For businesses that handle FCI but not CUI. It maps to 15 basic safeguarding requirements from federal acquisition rules, things like using strong access controls and keeping systems patched. Level 1 is met through an annual self-assessment.

Level 2 (Advanced). For businesses that handle CUI. It aligns with the 110 security requirements in NIST Special Publication 800-171, the federal standard for protecting CUI in non-government systems. Depending on the contract, Level 2 is met either by self-assessment or by a third-party assessment conducted by a certified assessor.

Level 3 (Expert). For the most sensitive programs, adding requirements from NIST SP 800-172 on top of Level 2, with government-led assessment. Most small businesses will never touch Level 3.

For the large majority of small contractors and subcontractors, the live questions are Level 1 versus Level 2, and that turns on whether CUI ever lands in your systems.

The flow-down question, which is how most small businesses get pulled in

Here is the part that catches owners off guard. You may have no direct contract with the DoD at all and still need CMMC, because of flow-down.

When a prime contractor wins a defense contract that involves FCI or CUI, the cybersecurity obligations do not stop at the prime. They flow down to the subcontractors who help perform the work, and to those subcontractors’ subcontractors. If you make a part, write code, provide engineering, or handle data anywhere in that chain, and CUI or FCI reaches you, the level the prime is held to generally flows to you for the work you do.

So the honest test is not “do I have a DoD contract.” It is: does any work I do, for anyone, involve federal contract information or controlled unclassified information from a defense program? If the answer is yes, CMMC almost certainly reaches you, and the prime above you will expect proof before they keep sending you work. The cleanest way to know is to ask your prime contractor directly which level your subcontract requires and whether any CUI will reach your systems. Get that answer in writing.

If no defense-related FCI or CUI ever touches your business, CMMC doesn’t apply to you, and you shouldn’t let anyone sell it to you as if it does.

What getting ready actually looks like

If CMMC does reach you, the work is concrete rather than mysterious. For Level 1, you put the 15 foundational safeguards in place and document that you did. For Level 2, the heavier lift, you implement the 110 NIST 800-171 controls, document each one in a System Security Plan, track anything not yet finished in a Plan of Action and Milestones, and post your score to the DoD’s Supplier Performance Risk System (SPRS).

That score matters. Many defense contracts already require a current SPRS self-assessment score under the existing DFARS clause, so even before a formal CMMC assessment, primes may be checking it. Getting your controls in place and your score posted accurately is the practical starting line.

This is the same layered, well-documented security work we describe in our People+ Framework: access control, encryption, monitoring, logging, and backups, applied to a specific federal standard and written down so it can be assessed. One caution worth stating plainly: no IT provider can hand you a certification. We can build and operate the controls and assemble the evidence, but the responsibility stays with your business, which is exactly the boundary we cover in whether an MSP can make you compliant.

To make the prep manageable, our CMMC Readiness and SPRS Prep Checklist walks through the NIST 800-171 controls in the order we tackle them with clients, so you can see your gaps before an assessor does.

Where to start

If a prime contractor has started asking about CMMC, or you suspect CUI is quietly flowing into your systems, the first step is simply to scope it: figure out what defense-related information you actually touch and which level that puts you at. From there the path is a real plan with real dates, not a panic. You can read more on our compliance hub, or sit down with us. We’re local, we work with contractors across Alaska and Hawaii, and we’ll give you a clear read on what applies to you and what doesn’t.

Book a Discovery Call